Thread: hijackthis help
View Single Post
Old 20-08-2004, 01:21 PM   #13 (permalink)
dpm
Member
 
Join Date: Aug 2003
Posts: 115
Thanks: 0
Thanked 0 Times in 0 Posts
Also,
O4 - HKCU\..\Run: [Cghpzsyz] C:\WINDOWS\System32\puw.exe
and
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Dawg\Application Data\ttuh.exe

look suspicious. Do you know if either of them are legitimate programmes?

Further,
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} (Personal System Administrator Control) - http://206.65.172.231/check/netset/...ll/gtdowngc.cab
and
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
look like spyware / browser hijackers to me. Do the programme names mean anything to you?
dpm is offline   Reply With Quote